CVEs (313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2P11 Kit Project Redhat4Enterprise Linux Hardened ImagesOpenshift Container Platform+1 moreJul 13, 2026 Jun 29, 2026 N/A· v4 6.2 MEDIUM· v3 N/A· v2 A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit...Show more |
2Kernel Redhat4Enterprise Linux Hardened ImagesOpenshift Container Platform+1 moreJul 8, 2026 Jun 29, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically alloca...Show more |
2Openbsd Redhat4Enterprise Linux Hardened ImagesOpenshift Container Platform+1 moreJul 8, 2026 Jun 23, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mo...Show more |
2Redhat Thekelleys3Dnsmasq Enterprise LinuxOpenshift Container PlatformJul 8, 2026 Jun 22, 2026 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write pa...Show more |
1Redhat 2Openshift Container Platform Windows Machine Config OperatorJul 15, 2026 Jun 22, 2026 N/A· v4 8.3 HIGH· v3 N/A· v2 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-...Show more |
1Redhat 2Openshift Container Platform Windows Machine Config OperatorJul 15, 2026 Jun 22, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes...Show more |
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and cou...Show more |
1Redhat 1Openshift Container Platform Jul 22, 2026 Jun 1, 2026 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create po...Show more |
1Redhat 2Openshift Container Platform Openshift RouterJul 24, 2026 May 29, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated a...Show more |
1Redhat 2Openshift Container Platform Openshift RouterJul 21, 2026 May 29, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud...Show more |
2Redhat Samba3Enterprise Linux Openshift Container PlatformSambaJul 15, 2026 May 28, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u subs...Show more |
2Redhat Samba3Enterprise Linux Openshift Container PlatformSambaJul 2, 2026 May 27, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validatio...Show more |
2Redhat Samba3Enterprise Linux Openshift Container PlatformSambaJul 15, 2026 May 27, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may cr...Show more |
2Redhat Samba3Enterprise Linux Openshift Container PlatformSambaJul 15, 2026 May 27, 2026 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreJul 23, 2026 May 26, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially...Show more |
2Redhat Samba3Enterprise Linux Openshift Container PlatformSambaJul 24, 2026 May 26, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreJul 23, 2026 May 21, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an under...Show more |
2Opensuse Redhat6Enterprise Linux Hardened ImagesLibsolv+3 moreJul 23, 2026 May 20, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by provi...Show more |
2Gnu Redhat14Enterprise Linux Enterprise Linux For ElsEnterprise Linux For Eus+11 moreJul 23, 2026 May 18, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence num...Show more |
2Gnu Redhat4Enterprise Linux GnutlsHardened Images+1 moreJul 23, 2026 May 7, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this...Show more |